NAME

IO::K8s::Types::Net - Type::Tiny constraints for IP addresses and CIDR notation

VERSION

version 1.110

SYNOPSIS

use IO::K8s::Types::Net qw( IPv4 IPv6 IPAddress CIDR NetIP );
use IO::K8s::Types::Net qw( parse_ip cidr_contains is_rfc1918 );

IPAddress->check('10.0.0.1');       # type constraints
my $ip = parse_ip('10.0.0.1');      # helper constructor
cidr_contains('10.0.0.0/8', $ip);  # CIDR containment test
is_rfc1918('192.168.1.1');          # RFC 1918 private-use test

DESCRIPTION

This module is a Type::Library bundling Net::IP-backed type constraints and helpers for working with IPv4/IPv6 addresses and CIDR ranges. It is the source of truth for IP / CIDR validation across IO::K8s -- both the IO::K8s::Role::CertManaged fluent builders and the IO::K8s::Role::NetworkPolicy CIDR checks run through these constraints.

Five Type::Tiny types are declared:

IPv4 -- single IPv4 addresses (no CIDR suffix).
IPv6 -- single IPv6 addresses (no CIDR suffix).
IPAddress -- either IPv4 or IPv6, no CIDR suffix.
CIDR -- CIDR-notation strings (the slash is mandatory).
NetIP -- Net::IP instances, with a coercion from plain strings.

Three helper functions are optionally exported:

parse_ip -- thin wrapper over Net::IP->new.
cidr_contains -- returns true iff an IP lies inside a CIDR.
is_rfc1918 -- true iff an IP lies inside one of the three RFC 1918 private-use ranges.

Each type and each function is documented under its own =func block below.

IPv4

use IO::K8s::Types::Net qw( IPv4 );

IPv4->check('10.0.0.1');   # 1
IPv4->check('10.0.0.1/8'); # undef (no CIDR suffix)

A Type::Tiny constraint accepting only strings that look like a single IPv4 address (no CIDR suffix). Validated via Net::IP; the constraint's diagnostic message is '$_' is not a valid IPv4 address.

IPv6

use IO::K8s::Types::Net qw( IPv6 );

IPv6->check('::1');      # 1
IPv6->check('10.0.0.1'); # undef

A Type::Tiny constraint accepting only single IPv6 addresses (no CIDR suffix). Validated via Net::IP. The diagnostic message is '$_' is not a valid IPv6 address.

IPAddress

use IO::K8s::Types::Net qw( IPAddress );

IPAddress->check('10.0.0.1');   # 1
IPAddress->check('::1');        # 1
IPAddress->check('10.0.0.0/8'); # undef (CIDR belongs in CIDR)

A Type::Tiny constraint accepting either IPv4 or IPv6 single addresses (no CIDR suffix). Validated via Net::IP -- a value is good iff Net::IP->new($_) constructs successfully. The diagnostic message is '$_' is not a valid IP address.

This is the type the "add_ip_san" in IO::K8s::Role::CertManaged sanity-check runs against; the role does the validation rather than installing the attribute as an IPAddress directly because Certificate CRDs accept arrays of plain strings on the wire.

CIDR

use IO::K8s::Types::Net qw( CIDR );

CIDR->check('10.0.0.0/8'); # 1
CIDR->check('10.0.0.1');   # undef (no slash)

A Type::Tiny constraint accepting only CIDR-notation strings (e.g. 10.0.0.0/8). The string must contain a /; Net::IP then has to parse the rest. The diagnostic message is '$_' is not valid CIDR notation.

NetIP

use IO::K8s::Types::Net qw( NetIP );

NetIP->check(Net::IP->new('10.0.0.1')); # 1

A Type::Tiny constraint accepting only Net::IP instances. Comes with a coercion: any plain string is run through Net::IP->new($_), so attributes declared NetIP can be constructed from a string. The coercion does no validation -- Net::IP::Error will tell you whether the result is usable.

parse_ip

my $ip = parse_ip('10.0.0.1');

Thin wrapper around Net::IP->new($str). Returns the Net::IP object on success, undef on failure. Optional export from IO::K8s::Types::Net.

if (my $ip = parse_ip($value)) {
    say "v", $ip->version;
}

cidr_contains

cidr_contains('10.0.0.0/8', '10.1.2.3'); # 1 (10.1.2.3 is in 10/8)
cidr_contains('10.0.0.0/8', '11.0.0.1'); # 0

Returns a true value iff $ip_str lies inside $cidr_str. Both inputs are run through Net::IP; either one failing to parse returns 0 (rather than croaking) so the function is safe to call on untrusted input. Optional export from IO::K8s::Types::Net.

is_rfc1918

is_rfc1918('192.168.1.1');    # 1
is_rfc1918('10.0.0.1');       # 1
is_rfc1918('172.16.5.5');     # 1
is_rfc1918('8.8.8.8');        # 0

Returns a true value iff $ip_str lies inside any of the three RFC 1918 private-use ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Implemented in terms of cidr_contains; an unparseable input is treated as not-RFC1918. Optional export from IO::K8s::Types::Net.

SEE ALSO

Net::IP, Type::Tiny, IO::K8s::Role::CertManaged, IO::K8s::Role::NetworkPolicy

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/pplu/io-k8s-p5/issues.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHORS

  • Torsten Raudssus <getty@cpan.org>

  • Jose Luis Martinez Torres <jlmartin@cpan.org>

COPYRIGHT AND LICENSE

This software is Copyright (c) 2018-2026 by Jose Luis Martinez Torres <jlmartin@cpan.org>.

This is free software, licensed under:

The Apache License, Version 2.0, January 2004